Re: KINK issue list

Michael Thomas <[email protected]> Fri, 04 Feb 2005 15:09:35 -0800
Newsgroups gmane.ietf.kink
Organization Cisco Systems
Message-ID <[email protected]>
On Mon, 2005-01-31 at 17:54, Kazunori Miyazawa wrote:
> Hello,
> 
> I have read the mails and I think these issues could be closed.
> 
> Kamada-san described the checksum calculation and verification in
> this mail.
> http://www.vpnc.org/ietf-kink/mail-archive/msg00336.html
> 
> If KINK adopts this, check sum length in KINK header will be two
> octets because kcrypto specifies that the output of get_mic is
> no longer than 65535 octets in the section 4.

Yes, there is an inconsistency in the draft in this
regard... the diagram which shows it as being one
octet actually more closely reflects reality (unfortunately).
I haven't thought very hard about how to resolve this.

> BTW, if there are no strong reason, I like to move the check sum
> field from the header to the end of message, because we could
> be easy to access KINK_AP_REQ/REP payload and forget it after
> verification.

Am I understanding you as saying that you'd like this
to not be in the KINK header at all? And instead be, 
like, in one of the payloads following the header? That
might be problematic given the KINK_ENCRYPT payload and
some other odd things that might surface.

		Mike
signature.asc (application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iQCVAwUAQgQAr7MsDAj/Eq++AQJHRAP/dzhp2mpsQ49m1ZvYhtcAWJi55SCTolK6
YuqACrlwy6YCdIRmaKAAz6gpimhj9ILv73OE0jyH/+AzbhNmYWYb4rsTUc3TnnEo
f39LL42Z0AGOg5BV4OYqQqMqeg5rMSry0A2HVsTpwBc0mb/41xqpOEZfj2JuAKhv
WU9277q1uO0=
=liqr
-----END PGP SIGNATURE-----